CCPs: Where DORA Meets Systemic Risk
Central counterparties are among the most systemically important entities in the financial system. When you buy or sell a derivative, the CCP stands between buyer and seller, guaranteeing both sides of the trade. If a CCP fails, the entire financial market seizes. Post-2008, regulators pushed more derivatives through central clearing (EMIR in the EU) — which reduced bilateral counterparty risk but concentrated risk in CCPs.
Under DORA, CCPs are classified as essential entities with the strictest requirements, including mandatory threat-led penetration testing (TLPT).
Critical CCP Systems
Real-Time Risk & Margining
- Real-time risk engine: Continuously calculates margin requirements across millions of positions. Latency requirements: sub-millisecond. Any disruption could trigger margin calls or fail to detect exposures.
- Margin calculation: Initial margin, variation margin, default fund contributions — all calculated multiple times daily. Errors directly affect financial stability.
- Default management: If a clearing member defaults, the CCP must auction the defaulter's portfolio and manage losses. This process is time-critical and must work under extreme stress.
- Settlement systems: Cash and securities settlement — must interface reliably with central securities depositories (CSDs) and payment systems (TARGET2).
Network & Connectivity
- Clearing member connectivity: Dedicated network connections to major banks and brokers. SLA requirements: 99.99%+ availability.
- Market data feeds: Real-time pricing for mark-to-market. Multiple source redundancy required.
- Regulatory reporting: EMIR reporting to trade repositories. Must continue even during incidents.
- Cross-CCP links: Interoperability agreements with other CCPs — failure propagation risk.
DORA Requirements for CCPs
Enhanced Requirements (Beyond Standard DORA)
- TLPT mandatory: CCPs must undergo threat-led penetration testing (TIBER-EU framework) at least every 3 years. Tests must cover critical functions including real-time risk engines.
- Recovery time objectives: 2-hour RTO for critical functions is the market standard. Some regulators expect same-day recovery for all functions.
- Third-party concentration risk: CCPs typically depend on a small number of critical vendors — Bloomberg (market data), SWIFT (messaging), major cloud providers (if using cloud). Each is a concentration risk.
- Board-level ICT governance: Management body must have adequate ICT expertise. Regular reporting on ICT risk posture, incidents, and testing results.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →EMIR Interaction
CCPs already operate under EMIR's operational risk requirements. DORA adds and harmonises:
- EMIR RTS on CCP resilience: Existing requirements for BCP, disaster recovery, and operational risk management. DORA doesn't replace these but adds ICT-specific requirements on top.
- Incident reporting: DORA creates a harmonised reporting framework. CCPs previously reported to NCAs under EMIR — now also under DORA with stricter timelines.
- Third-party oversight: DORA's Critical Third-Party Provider (CTPP) framework may designate CCP technology vendors as CTPPs — subjecting them to direct oversight by European Supervisory Authorities.
- Proportionality: Limited for CCPs. As systemically important entities, they face the full weight of DORA requirements.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton